Skip to content

Information Security Policy

Document Control

Document Information
Document Name Document Number Implementation Date Next Review Date Policy Owner
Information Security Policy CYS-ISP-01/2025 2025-10 2026-10 Cybersecurity GRC Consultant
Revision History
Version Name Job Title Date Summary of Revision
1 no-one N/A Cybersecurity GRC Consultant 1st Release
Document Approvals
Name Title Date Method
Abdullah Alqhatani CISO 2025-10 Email

Purpose

Masdr is committed to protecting the confidentiality, integrity, and availability of all its information assets. Information security is a fundamental component of Masdr's operations and is essential to maintaining trust with users, partners, regulators, and other stakeholders.

This Information Security Policy establishes Masdr's overall direction and principles for information security and provides the foundation for the Information Security Management System (ISMS). The purpose of this policy is to:

  • Define Masdr's commitment to information security
  • Establish a high-level framework for managing information security risks
  • Ensure compliance with applicable national, legal, regulatory, and contractual requirements
  • Support the secure delivery of Masdr's products and services

Scope

This policy applies to:

  • All information assets owned, processed, or managed by Masdr, regardless of format or location
  • All Masdr personnel, including employees, contractors, temporary staff, and third parties
  • All information systems, applications, infrastructure, and services, including cloud-based and third party environments

Compliance

Compliance with this policy is mandatory. Failure to comply with this policy may result in disciplinary action, up to and including termination of employment or contract, as well as potential legal consequences.


Definitions

Term Definition
Policy Owner The individual responsible for maintaining and updating this policy.
User Any person who accesses or uses Masdr's systems, data, or networks.
ICT Information and Communications Technology.
Information Security Preservation of confidentiality, integrity, and availability of information.
Information Security Management System (ISMS) Policies, procedures, guidelines, and associated resources and activities, collectively managed by an organization, in the pursuit of protecting its information assets.
Availability Property of being accessible and usable on demand by an authorized entity.
Confidentiality Property that information is not made available or disclosed to unauthorized individuals, entities, or processes.
Integrity Property of accuracy and completeness.
Top management Person or group of people who directs and controls an organization at the highest level

Roles and Responsibilities

Role Responsibility
Policy Owner Ensure the policy is maintained, reviewed, and updated regularly.
All Employees Understand and adhere to the requirements of this policy.
Managers Communicate policy requirements to their teams and ensure compliance.

Policy Statements

Information Security Objectives

Masdr establishes information security objectives that are consistent with its strategic direction and regulatory obligations.

The information security objectives of Masdr are to:

  • Promote and ensure the secure, responsible, and controlled use, development, adoption, and access to Artificial Intelligence technologies
  • Protect sensitive, personal, financial, and health-related information from unauthorized access, disclosure, alteration, or destruction
  • Ensure the availability and resilience of information systems supporting Masdr's operations and services
  • Mange information security risks through a structured risk assessment and treatment process
  • Maintain compliance with applicable national decrees, laws, regulations, and national cybersecurity requirements within the Kingdom of Saudi Arabia
  • Promote information security awareness and accountability throughout Masdr
  • Continually improve the suitability, adequacy and effectiveness of Masdr's ISMS

Management Commitment

Masdr’s top management demonstrates leadership and commitment to the ISMS by:

  • Establishing and approving this Information Security Policy
  • Ensuring information security objectives are defined and aligned with business goals
  • Providing adequate resources, including funding, personnel, and technology, to operate and improve the ISMS
  • Assigning clear roles, responsibilities, and authorities for information security
  • Supporting continual improvement of information security performance
  • Promoting a culture of information security awareness and compliance

Information Security Policy Framework

Masdr maintains a structured framework of information and cyber security documentation to support this policy, which can be accessed through the policies portal. All personnel should apply information security in accordance with the Information Security Policy, topic-specific policies and procedures of Masdr.

This policy is supported by, and takes precedence over, all subordinate information security standards and procedures.

Information Security Responsibilities

Information security is a shared responsibility across Masdr. The table below outlines the key roles and their responsibilities related to the ISMS:

Role Responsibilities
Top Management Provide strategic direction, oversight, and resources for the ISMS.
Information Security / ISMS Function Develop, implement, maintain, and monitor the ISMS
Business Units Managers Ensure their teams understand and comply with applicable information security requirements
Employees and Third Parties Understand and follow information security policies, standards, and procedures, and promptly report any suspected or confirmed information security incidents, weaknesses, or non-conformities.

Exceptions

Requests for exceptions to this policy must be submitted in writing to the Policy Owner. Exceptions will be reviewed on a case-by-case basis and must be formally approved before any deviation is permitted.

  • All exceptions MUST be documented and approved by the Policy Owner and Information Security.
  • Exceptions MUST include a defined expiration date.
  • Compensating controls MUST be identified where applicable.
  • All exceptions MUST be reviewed at least annually.